You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Let openApiTools() (src/tools/openapi/) refuse private destinations with the same pinned DNS lookup that http_request and web_fetch use since #255 / #277, for applications whose OpenAPI base URL (or the document URL) is not fully under their control.
Current state
openApiTools() sends every request (and the document fetch) through options.fetch ?? fetch, with no private-address check. docs/openapi-tools.md ("Security", bullet "No private-address check") says so and tells users to put a proxy in front or pass their own fetch.
It is not a small, contained change; it needs public API decisions:
Default. openApiTools deliberately allows http: for localhost, 127.0.0.1, [::1], and base URLs are developer-configured, often internal APIs on private addresses. Turning the check on by default would break those; turning it on by opt-in needs a new option (e.g. privateAddresses: 'allow' | 'refuse' plus allowPrivate host patterns).
Interaction with the fetch option (a user-supplied fetch cannot be given a dispatcher portably), and with the document fetch in loadDocument().
Runtime: undici and node:dns are Node only; check whether openApiTools is meant to work on Workers / edge before adding them to its path.
Alternatively export a public helper (e.g. createPinnedFetch({ allowPrivate })) that users pass as fetch, which also serves custom tools.
Scope
Decide one of the above, implement it with a test that a base URL resolving to a private address (stubbed resolver) is refused and that a rebinding name (public first, 127.0.0.1 second) never reaches a local server, and update the "No private-address check" bullet in docs/openapi-tools.md plus a CHANGELOG entry.
Goal
Let
openApiTools()(src/tools/openapi/) refuse private destinations with the same pinned DNS lookup thathttp_requestandweb_fetchuse since #255 / #277, for applications whose OpenAPI base URL (or the document URL) is not fully under their control.Current state
openApiTools()sends every request (and the document fetch) throughoptions.fetch ?? fetch, with no private-address check.docs/openapi-tools.md("Security", bullet "No private-address check") says so and tells users to put a proxy in front or pass their ownfetch.src/security/privateAddress.ts(added by [N13a] web_fetch built-in with pinned-DNS SSRF checks; http_request no longer open to DNS rebinding #277) hasisPrivateAddress(),resolvePublicAddresses()andpinnedLookup();http.tsandwebFetch.tsuse it through an undiciAgent({ connect: { lookup: pinnedLookup({ allowPrivate }) } }). The module is internal: nothing is exported from the package root.Why it was not done in #277
It is not a small, contained change; it needs public API decisions:
openApiToolsdeliberately allowshttp:forlocalhost,127.0.0.1,[::1], and base URLs are developer-configured, often internal APIs on private addresses. Turning the check on by default would break those; turning it on by opt-in needs a new option (e.g.privateAddresses: 'allow' | 'refuse'plusallowPrivatehost patterns).fetchoption (a user-suppliedfetchcannot be given a dispatcher portably), and with the document fetch inloadDocument().node:dnsare Node only; check whetheropenApiToolsis meant to work on Workers / edge before adding them to its path.createPinnedFetch({ allowPrivate })) that users pass asfetch, which also serves custom tools.Scope
Decide one of the above, implement it with a test that a base URL resolving to a private address (stubbed resolver) is refused and that a rebinding name (public first, 127.0.0.1 second) never reaches a local server, and update the "No private-address check" bullet in docs/openapi-tools.md plus a CHANGELOG entry.
Found while finishing #255 (PR #277).